highCVSS 8.8Vulnerability

GHSA-hw9r-h9mr-4jff

### Summary Some internal command handlers require `operator.approvals` or `operator.admin` scopes. In affected releases, a scoped Gateway `chat.send` request delivered through an inherited external route could be evaluated as an external-channel command while still carrying the lower Gateway client scopes. This issue affects scoped Gateway clients. It does not apply to shared-secret bearer HTTP compatibility endpoints, which are documented as full operator surfaces under OpenClaw's trust model. ### Affected configurations This affects deployments where a scoped Gateway caller with `operator.write` can use `chat.send` with delivery into a session that has an inherited external delivery route. ### Impact Commands that should have required `operator.approvals` or `operator.admin` could run with only `operator.write` in this routed context. Affected command families included approval resolution and selected administrative commands such as plugin, config, MCP, allowlist, and ACP mutations. ### Patched Versions The first stable patched version is `2026.5.18`. ### Mitigations Upgrade to `[email protected]` or later. Before upgrading, avoid granting `operator.write` tokens to clients that can deliver commands into sessions with external routes unless those clients are trusted with admin-like command effects.

Properties

ghsa_id
GHSA-hw9r-h9mr-4jff
summary
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
severity
high
cvss_score
8.8
cve_id
GHSA-hw9r-h9mr-4jff
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-07-02T16:06:00Z
source_url
https://github.com/advisories/GHSA-hw9r-h9mr-4jff
ghsa_updated
2026-07-02T16:06:00Z

Related Entities (5)

AFFECTS (1)

[Software]npm/openclaw

HAS_WEAKNESS (2)

[Weakness]Missing Authorization
[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/openclaw

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-hw9r-h9mr-4jff (CVSS 8.8) — Ninja Signal Threat Intelligence | Ninja Signal